pkg:Maven/org.springframework:spring-core

18 total CVEsHIGH7MEDIUM6

✅ Check your installed version

All known vulnerabilities

  • HIGH8.8CVE-2018-1258Spring Framework when used in combination with any versions of Spring Security contains an authorization bypass
    >= 5.0.5.RELEASE, < 5.0.6.RELEASE
  • HIGH8.6CVE-2015-5211Files or Directories Accessible to External Parties in org.springframework:spring-core
    >= 4.2.0, < 4.2.2
  • HIGH7.5CVE-2025-41249Spring Framework annotation detection mechanism may result in improper authorization
    >= 5.3.0, <= 5.3.44
  • HIGH7.5CVE-2024-22233Spring Framework server Web DoS Vulnerability
    >= 6.1.2, < 6.1.3
  • HIGH7.5CVE-2018-15756Denial of Service in Spring Framework
    >= 5.1.0.RELEASE, < 5.1.1.RELEASE
  • HIGH7.5CVE-2016-5007Spring Security and Spring Framework may not recognize certain paths that should be protected
    from 0, < 4.3.1
  • HIGH7.5CVE-2018-1272Possible privilege escalation in org.springframework:spring-core
    from 0, < 4.3.15
  • MEDIUM6.5CVE-2018-1257Denial of Service in org.springframework:spring-core
    >= 5.0.0, < 5.0.6
  • MEDIUM5.9CVE-2018-1271Path Traversal in org.springframework:spring-core
    >= 5.0.0, < 5.0.5
  • MEDIUM5.9CVE-2018-11040Moderate severity vulnerability that affects org.springframework:spring-core
    >= 5.0.0.RELEASE, < 5.0.7.RELEASE
  • MEDIUM5.3CVE-2018-1199Improper Input Validation in org.springframework.security:spring-security-core, org.springframework.security:spring-security-core , and org.springframework:spring-core
    >= 4.3.0, < 4.3.14
  • MEDIUM4.3CVE-2021-22096Improper Output Neutralization for Logs in Spring Framework
    >= 5.3.0, < 5.3.11
  • MEDIUM4.3CVE-2021-22060Log entry injection in Spring Framework
    >= 5.3.0, < 5.3.14
  • CVE-2011-2730libspring-2.5-java - information disclosure
    >= 3.0.0, < 3.0.6
  • CVE-2011-2894Spring Framework and Spring Security vulnerable to Deserialization of Untrusted Data
    >= 3.0.0, < 3.0.6
  • CVE-2014-3578libspring-java - security update
    >= 3.0.0, < 3.2.9
  • CVE-2009-1190Spring Framework Inefficient Regular Expression Complexity
    >= 1.1.0, < 3.0.0.RELEASE
  • CVE-2015-0201Moderate severity vulnerability that affects org.springframework:spring-core
    >= 4.1.0, < 4.1.5